Endpoint 7.13 migration to 7.13.1 Lesson learned with Fleet “On-Prim” -Bad

I assume you mean the disk on the computer running Agent, not your Elasticsearch node? Can you share the paths to the files on your computer are filling up the disk.

For "got about 2x10^6 events" can you share the indices these events are going to?

Is this issue what you are seeing? If so, an upgrade to 7.13.0+ should resolve the issue.